Clop's Quiet Two-Month Extortion Campaign Just Went Public — and Analysts Called It Weeks Ago
A look at the last 24 hours in cybersecurity: the Shell and Philips leak-site listings this week are the public phase of a Clop campaign that's been running silently since June, and SAP Commerce Cloud exploitation continues to widen.
Sometimes the news isn't the incident, it's the timeline — and today's is worth laying out in full, because it explains something that looked sudden earlier this week but wasn't. Clop's exploitation of PTC Windchill and FlexPLM, the campaign behind this week's Shell, Philips, GE, and Fiserv leak-site listings, didn't start this week. It started on June 17, the day PTC patched CVE-2026-12569, a critical improper input validation flaw in both platforms. Exploitation in the wild was flagged the very next day. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 25. For nearly a month after that, Clop ran the campaign entirely in private: chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to plant hex-named JSP webshells, quietly exfiltrating engineering and design data from manufacturing, automotive, aerospace, and retail organizations. Starting July 20, victims began receiving extortion emails with the subject line "Windchill PDMLink module serious data leak," sent from compromised third-party accounts to hundreds of recipients inside each target organization at once — a pressure tactic that guarantees the incident becomes visible internally before security teams have finished scoping it, and one that slips past sender-authentication checks precisely because the emails don't come from attacker-registered domains.
Through all of that, Clop stayed quiet publicly. As of July 28, threat intelligence analysts tracking the campaign noted that no victims had been listed on Clop's leak site and no credit had been publicly claimed — and explicitly assessed that silence as characteristic of the group's established playbook rather than a reassuring sign, predicting a naming wave "in the August-September window" based on the same pattern Clop ran against Oracle E-Business Suite last year: exploit, exfiltrate, extort privately, then mass-publish once private negotiations stall. That's exactly what's happening now. This week's public listings of Shell, Philips, and reportedly GE and Fiserv aren't a new attack — they're that predicted second phase arriving on schedule. If your organization runs Windchill or FlexPLM and hasn't already hunted for hex-named webshells under the Windchill login path going back to early June, the two-month head start Clop has already had makes that overdue, not optional. Legitimate traffic doesn't POST to that login path at all, which makes it a higher-fidelity detection signal than trying to match webshell filenames that change between deployments.
Separately, the SAP Commerce Cloud story from earlier this week continues to develop in the direction you'd expect. CVE-2026-58231, the CVSS 10.0 unauthenticated RCE in the platform's Data Hub Adapter extension, is still seeing exploitation attempts against exposed instances, with no public proof-of-concept in circulation and no confirmed successful compromise disclosed publicly yet — meaning the window to patch ahead of a working exploit chain, rather than behind one, is still technically open for organizations that haven't yet applied SAP's August Patch Day fix. That window narrows daily; treat it as closed regardless of what's confirmed publicly, and patch on the assumption that someone, somewhere, already has a working chain they haven't advertised.
Two stories, one lesson worth repeating from earlier this week because it keeps proving true: the gap between a vendor's patch notes and a working exploit is no longer measured in weeks. For Clop, that gap was one day. For SAP Commerce Cloud, three. Patch cadence built around monthly or quarterly review cycles isn't a defense against timelines like that — it's an invitation to be the organization still investigating in September what analysts already told you to expect in July.
- Ransom-ISAC — Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
- isMalicious — Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data
- BankInfoSecurity — Clop Tied to PTC Product Life Cycle Management Software Hits
- BleepingComputer — Shell Investigates Potential Incident After Clop Data Theft Claims
- The Hacker News — SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts
